Privacy Policy
Last updated: March 2026
Stone Rank Kft. ("we", "us", "our") operates Trust Agency. This Privacy Policy explains how we collect, use, and protect your personal data.
Data We Collect
- Listing data: the business name, website, location, services and contact details submitted when a listing is created or edited.
- Contact form data: name, email, phone number, and message when you submit a contact or quote request.
- Usage data: pages visited, browser type, and IP address via analytics tools.
- Google Search Console data: performance metrics (clicks, impressions, CTR, positions) when agency owners connect their GSC account.
Google Search Console Integration
Listing owners can optionally connect their Google Search Console account to enrich their page with real performance data. Here is how we handle it:
- Connection is entirely voluntary, free, and can be revoked at any time.
- All performance data displayed publicly is anonymized and aggregated: no individual queries, pages, or user-level data is ever exposed.
- We only access read-only data (clicks, impressions, CTR and positions). We never modify your Google account.
- We do not store raw Google data long-term. Data is processed and aggregated, then only the anonymized metrics are retained.
- You can revoke our access at any time from your Google account permissions page. Write to us and we will delete the associated data.
Data Deletion
To have your data deleted, write to us from the email address concerned. We remove the listing data, any connected Search Console data and the associated performance metrics, then confirm by email.
How We Use Your Data
- To provide and improve the Trust Agency directory.
- To transmit contact requests to the relevant agencies.
- To send newsletters if you opted in (you can unsubscribe anytime).
- To display public performance data on profiles that opted in.
Data Sharing
We do not sell your personal data. We may share data with: the entity you contact through our forms, our hosting provider (Vercel), our authentication and database provider (Supabase), and our payment provider (Stripe).
Cookies
We use a small number of essential cookies to remember your language and theme. We do not use advertising cookies. You can manage cookies through your browser settings.
Your Rights
Under GDPR, you have the right to access, rectify, delete, and port your personal data. You can also object to processing or request restriction. To exercise your rights, contact us at the address below.
Data Protection & Security
- All data in transit is encrypted using HTTPS/TLS encryption.
- Data at rest is stored securely in Supabase, protected by Row Level Security (RLS) policies.
- Google OAuth tokens are stored securely and are only used to fetch read-only data on your behalf. You can revoke access at any time from your Google account settings.
- We request only the minimum OAuth scope necessary: webmasters.readonly for Google Search Console. We never request write access to your Google account.
- Access to sensitive data (such as Google tokens) is restricted by server-side access controls.
- We conduct regular reviews of our data handling practices and promptly address any identified vulnerabilities.
Google OAuth Scopes
When you connect your Google account, we request the following limited, read-only scopes:
- Google Search Console: webmasters.readonly - allows us to read your search performance data (clicks, impressions, CTR, positions). We cannot modify your Search Console settings or data.
- Email - used solely to identify your Google account and match it to your Trust Agency listing.
Contact
For any privacy-related inquiry, please reach out via our contact page.
